| Old News, Press Releases, Store Notifications Archive containing old News Threads, Press Releases and Store Notifications |
 |
|
21-05-2008, 06:17 PM
|
#1 (permalink)
|
|
Administrator
Join Date: Sep 2005
Location: Manchester UK
Posts: 20,698
|
Security vunerability for Windows CE posted
A security vunerability for Windows CE posted in the US-CERT Cyber Security Bulletin.
Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted JPEG and GIF images.
For more details see National Vulnerability Database (CVE-2008-2160)
And update is available from Microsoft here.
|
|
|
21-05-2008, 06:32 PM
|
#2 (permalink)
|
|
Site Moderator
Join Date: May 2007
Location: New Jersey, USA
Posts: 1,048
|
Re: Security vunerability for Windows CE posted
Ok, here we go again... how long before I truly have to worry about browsing using my device...? PLEASE LET US BE... all we wanna do is enjoy our devices, like the truly addicted people we are... 
__________________
debonairone - Moderator
HTC TyTn (Hermes 200)
Suffering from Rom Flash Withdrawal Syndrome
If you enjoy this site then please ensure it's survival with a Donation or a Subscription.
|
|
|
21-05-2008, 06:44 PM
|
#3 (permalink)
|
|
Administrator
Join Date: Sep 2005
Location: Manchester UK
Posts: 20,698
|
Re: Security vunerability for Windows CE posted
Yeah but with this one MS do seem to acknowledge it and a fix issued.
|
|
|
23-05-2008, 02:18 AM
|
#4 (permalink)
|
|
Site Moderator
Join Date: May 2007
Location: New Jersey, USA
Posts: 1,048
|
Re: Security vunerability for Windows CE posted
It's not the fact that the vulnerability exists, it's the fact that there are those that will exploit it that bothers me... As intelligent as they are, please put that gray matter to use for my benefit, not the opposite...
But I am grateful that M$ has acknowledged it and issued a patch...
Deb.
__________________
debonairone - Moderator
HTC TyTn (Hermes 200)
Suffering from Rom Flash Withdrawal Syndrome
If you enjoy this site then please ensure it's survival with a Donation or a Subscription.
|
|
|
23-05-2008, 02:47 PM
|
#5 (permalink)
|
|
Administrator
Join Date: Sep 2005
Location: Manchester UK
Posts: 20,698
|
Re: Security vunerability for Windows CE posted
Yep, unfortunately there are always idiots out there who will take advanage of such things!
|
|
|
27-05-2008, 11:06 AM
|
#6 (permalink)
|
|
Site Moderator
Join Date: Sep 2005
Posts: 13,343
|
Re: Security vunerability for Windows CE posted
I agree with Jeff, the sad fact is that some of these virus writer types are very talented individuals. If only they'd put their talent to helping the community imagine how quickly the software world could progress. They might even make a buck or two too.
__________________
Waveydavey
4WM Moderator & Reviewer.
Microsoft MVP - Windows Mobile Devices.
|
|
|
27-05-2008, 01:01 PM
|
#7 (permalink)
|
|
Site Moderator
Join Date: Nov 2005
Location: Isle of Man
Posts: 3,045
|
Re: Security vunerability for Windows CE posted
For a long time mobile OSs have been considered far more secure than their desktop brethren. One of the (several) reasons for this was the lack of a permanant internet connection. As many people are now keeping their data connections permanantly open, thanks to all you can eat data plans, this restriction has dissappeared.
Still, devices are set up by default to ask the user before installing apps and to ask before sending data so they are pretty secure with a bit of common sense. I wonder how long it will be, though, before these things are bypassed for the sake of "ease of use", particularly in a corporate sense.
It makes huge sense to be able to bypass user interaction when deploying software, updates, sending data etc. from a Corporate standpoint. If you're deploying an update to 1000 devices you want minimum interaction. However, once the facilities are in the OS, it's only a matter of time before someone comes up with a way of exploiting it.
__________________
---
Ericsson R380, Nokia 7650, SE T68, SE P800, SE P900, XDA II, XDA IIs, XDA MiniS +2GB mSD, HTC Touch Cruise + 8GB MicroSDHC
|
|
|
27-05-2008, 03:07 PM
|
#8 (permalink)
|
|
Site Moderator
Join Date: Sep 2005
Posts: 1,503
|
Re: Security vunerability for Windows CE posted
Is it just me, or what was the point of having the update facility in WM? The patch has to be built into the base build, so HTC would have to package it into their ROM builds AFAIK.
It also requires user input as below
"Access Vector: Network exploitable , Victim must voluntarily interact with attack mechanism"
So in terms of bang for buck it really isn't the type of thing that would be attractive to cybercrime when there are far better vulnerable systems with a guaranteed fast internet connection.
__________________
Bydandie
Moderator
4Winmobile.com
Previous devices: T-Mob MDA Touch 256Mb, T-Mob MDA Touch 128Mb, T-Mob Ameo (WM6), Qtek v1605, T-Mob Vario, Moto MPx220, O2 XDAII, Dell Axim X5
|
|
|
28-05-2008, 12:14 AM
|
#9 (permalink)
|
|
Site Moderator
Join Date: May 2007
Location: New Jersey, USA
Posts: 1,048
|
Re: Security vunerability for Windows CE posted
Ha... Good point... I even tried using the update facility, just to see what would be updated, at least while the cooks left it in the rom...
As for the why would anyone bother with WM devices, the singular (not to be confused with Cingular) question would be, "I wonder if I can..?" And once they can, everyone can...
__________________
debonairone - Moderator
HTC TyTn (Hermes 200)
Suffering from Rom Flash Withdrawal Syndrome
If you enjoy this site then please ensure it's survival with a Donation or a Subscription.
|
|
|
28-05-2008, 07:29 AM
|
#10 (permalink)
|
|
Site Moderator
Join Date: Sep 2005
Posts: 1,503
|
Quote:
Originally Posted by debonairone
Ha... Good point... I even tried using the update facility, just to see what would be updated, at least while the cooks left it in the rom...
As for the why would anyone bother with WM devices, the singular (not to be confused with Cingular) question would be, "I wonder if I can..?" And once they can, everyone can...
|
The point though Deb is that almost all attacks have been for financical gain over the past four yeafs. Almost all attacks form part of the botnet cycle to gather information from systems. The fact remains that exploits like GDI rely on a feaure-rich browser and enough bandwidth to download the payload. Neither of which is prevalent in WM devices and the market share of WM is miniscule compared to all other smartphones.
Posted via Mobile Device
|
|
|
 |
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
Friends of 4WM
|
All times are GMT. The time now is 12:03 AM.
|
Sponsors |
|
|
|